Malware

Win32/Kryptik.HKAW information

Malware Removal

The Win32/Kryptik.HKAW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKAW virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:19764
  • A process created a hidden window
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Steals private information from local Internet browsers
  • Attempts to execute a powershell command with suspicious parameter/s
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.HKAW?


File Info:

crc32: 000AC190
md5: 370f42a2303ac2c56c457491d1739544
name: 370F42A2303AC2C56C457491D1739544.mlw
sha1: 2ac0ee86cde72a747608bf75aca2e640e4b8b8c4
sha256: 64a9348debe903442ef81b80ae4b8c72506d1fd50dac36dad23e561020c2a9de
sha512: f926ddee8eda9df69fce4e48388906fbb014f9b140a01764a3280df93dd5363a23ddf41582d3cd1484f936168cd35378569ace7bcbcc96b962ad80fde5b8dd53
ssdeep: 98304:UiKbZAC5V9ejyJqMih9j+9t83vcDjUJsLvQhLh7M7y/hcu:UiKbZAIig+1qY0vVALiGZX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.5.8.28
FileVerus: 1.0.2.27
Translations: 0x0126 0x0230

Win32/Kryptik.HKAW also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.46332
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.73607
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Glupteba.8187b811
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKAW
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.GenericKDZ.73607
MicroWorld-eScanTrojan.GenericKDZ.73607
Ad-AwareTrojan.GenericKDZ.73607
SophosMal/Generic-R
BitDefenderThetaGen:NN.ZexaF.34628.@xW@aeqn@xjG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.370f42a2303ac2c5
EmsisoftTrojan.GenericKDZ.73607 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Glupteba.lsfud
MicrosoftTrojan:Win32/Glupteba.PG!MTB
ArcabitTrojan.Generic.D11F87
AegisLabRiskware.Win32.Generic.1!c
GDataTrojan.GenericKDZ.73607
AhnLab-V3CoinMiner/Win.Glupteba.R373266
Acronissuspicious
McAfeePacked-GDK!370F42A2303A
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingMalware.Obscure/Heur!1.A89F (CLOUD)
IkarusTrojan-Banker.UrSnif
FortinetW32/Kryptik.HKAZ!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.ShellCode.HwoCBeMA

How to remove Win32/Kryptik.HKAW?

Win32/Kryptik.HKAW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment